#0001
Zscaler ThreatLabz8 days ago8 min▣LLM reportmedium Zscaler ThreatLabz observed a seasonal spike in web skimming and phishing campaigns targeting Black Friday and Cyber Monday shoppers. The Grelos skimmer group injected obfuscated JavaScript into e-commerce sites (both Magento and WooCommerce) to capture payment card data, using cookies for staging and base64 encoding for exfiltration disguised as benign traffic. Attackers also compromised legitimate deal websites to redirect users to malicious domains, and numerous newly registered holiday-themed domains were observed.
#0002
Zscaler ThreatLabz9 days ago10 min▣LLM reporthigh Thanos ransomware, a C#/.NET-based RaaS platform whose builder source code leaked, spawned at least four double-extortion variants in 2021: Prometheus, Haron, Spook, and Midas. All variants share common signatures including the 'GotAllDone' file marker appended to encrypted files and key identifiers in ransom notes. The latest variant, Midas, terminates security and backup services, deletes shadow copies, disables the Raccine anti-ransomware tool, encrypts files using Salsa20 with RSA-wrapped keys, and maintains persistence via a startup LNK file.
#0003
Zscaler ThreatLabz10 days ago7 min▣LLM reportmedium Zscaler ThreatLabz identified six Facebook phishing domains registered on 02/13/2011 by the same individual in China. The domains host identical fake Facebook login pages that capture user credentials before redirecting victims to legitimate Facebook or Google. The campaign leverages fast-flux DNS with rapidly rotating IP addresses and a shared DNS server (fbnameserver.com) previously tied to other Facebook phishing operations, making takedowns and blocklisting difficult.
#0004
Zscaler ThreatLabz12 days ago11 min▣LLM reporthigh ThreatLabz documents a threat actor cluster, likely an initial access broker for ransomware operations, that gains access via Microsoft Teams vishing and Quick Assist remote sessions, then deploys PowerShell staging scripts to install a multi-variant Go-based backdoor (GoGRPC) that communicates over gRPC/HTTP2 - an unusual choice for external C2 that blends with legitimate application traffic. The toolkit has expanded to include additional backdoors, SOCKS proxy tunneling tools (RevSocket, PyGRPC, RSOX), and an S3-based exfiltration utility (S3Siphon), reflecting increasing sophistication and selective targeting of corporate/enterprise environments since mid-2026.
#0005
Zscaler ThreatLabz13 days ago8 min▣LLM reportmedium Zscaler ThreatLabZ documents a seasonal increase in malicious activity coinciding with Black Friday/Cyber Monday shopping, including domain squatting on the '.blackfriday' TLD to impersonate Google and distribute the Fareit and Loki infostealers, browser-based cryptocurrency mining scripts embedded in shopping-themed sites, fraudulent e-commerce storefronts, and spear-phishing documents using holiday bonus/gift card lures to deliver embedded malicious applications. The techniques primarily rely on social engineering and typosquatted infrastructure rather than software exploitation.
#0006
Zscaler ThreatLabz14 days ago10 min▣LLM reporthigh Emotet, a prolific banking-trojan-turned-initial-access-broker, returned to the threat landscape on November 14, 2021 following a law enforcement disruption and arrests in January 2021. The revived variant is being distributed via the TrickBot botnet and direct spam campaigns using reply-chain phishing emails with malicious macro-enabled Office documents and password-protected archives, and now communicates with C2 infrastructure over HTTPS with updated encryption compared to prior versions.
#0007
Zscaler ThreatLabz14 days ago6 min▣LLM reportlow The article describes anti-analysis techniques found in certain Android malware samples designed to crash the AndroGuard APK analysis tool or its Python zipfile dependency, similar to anti-debugging tricks used by PC malware against tools like OllyDbg and IDA Pro. Techniques include crafting malformed 'linksize'/'linkoff' padding values that trigger unpack() failures due to 4-byte alignment issues in zipfile.py, and manipulating AndroGuard's search_methods() return values to conceal malicious behaviors like audio recording. The AndroGuard project addressed the zipfile parsing issue in a December 2012 patch.
#0008
Zscaler ThreatLabz17 days ago11 min▣LLM reporthigh A China-nexus threat actor, assessed with medium confidence to be Mustang Panda, conducted a multi-stage attack campaign targeting the Arabian Gulf region using Middle East conflict-themed social engineering lures. The attack chain delivered a PlugX backdoor variant through a ZIP archive containing a malicious LNK file that downloaded a CHM file via cURL, extracted a TAR archive using hh.exe, and used DLL sideloading to execute heavily obfuscated shellcode. The PlugX variant supports HTTPS and DNS-over-HTTPS (DOH) for C2 communication and employs advanced obfuscation including control flow flattening, mixed boolean arithmetic, corrupted MZ/PE headers, and reflective DLL injection.
#0009
Zscaler ThreatLabz19 days ago9 min▣LLM reporthigh Domain fronting is a network evasion technique where an attacker conceals the true destination of HTTPS traffic by using a trusted domain in the TLS SNI field while specifying a different malicious destination in the HTTP Host header, both served by the same CDN. The article details real-world abuse of Azure, Cloudflare, and Discord CDNs for C2 traffic and phishing, and describes domain hiding via ESNI as a related emerging threat. Effective defense requires full TLS inspection with SNI-Host header mismatch detection and ESNI stripping at the proxy layer.
#0010
Zscaler ThreatLabz19 days ago10 min▣LLM reporthigh Zscaler ThreatLabz identified a multi-stage attack campaign targeting Middle East government entities by a threat actor linked to East Asia. The attack chain uses an ISO file to deliver the TELESHIM backdoor via DLL sideloading of a legitimate ASUS executable, with TELESHIM abusing the Telegram API for C2 communication. A second-stage loader, MIXEDKEY, uses environmental keying based on the victim's volume serial number to decrypt and reflectively load the final BINDCLOAK C2 implant, with heavy obfuscation and anti-analysis techniques throughout.
#0011
Zscaler ThreatLabz23 days ago9 min▣LLM reporthigh GuLoader is a highly obfuscated malware-as-a-service downloader that has evolved since 2019 to deliver secondary payloads such as RATs and information stealers. It employs polymorphic code for dynamic constant construction, exception-based control flow obfuscation using five distinct CPU exception types, encrypted strings with stack-based decryption, and modified DJB2 API hashing. Payloads are hosted on trusted cloud platforms (Google Drive, OneDrive) to evade reputation-based detection, and the malware continues to receive updates increasing analysis complexity.
#0012
Zscaler ThreatLabz24 days ago10 min▣LLM reporthigh A MacSync Stealer campaign abuses Anthropic's Claude shared chat platform to host ClickFix-style malicious instructions, using Google malvertising to lure macOS users searching for Claude. Victims are tricked into running a Base64-obfuscated curl command that pipes a zsh script to execution, which in turn downloads and pipes a second stage to osascript. The stealer collects keychain data, browser credentials, cryptocurrency wallets, cloud keys, and user files, exfiltrating them in 10MB chunks via HTTP PUT before deleting all traces.
#0013
Zscaler ThreatLabzabout 1 month ago9 min▣LLM reportmedium Zscaler ThreatLabz identified two campaigns leveraging Indirect Prompt Injection (IPI) to manipulate AI agents via malicious websites. The first campaign uses SEO poisoning and hidden IPI instructions on a fraudulent API documentation site to trick AI agents into sending cryptocurrency payments for a fake API key. The second campaign uses a typosquatting domain (debank.auction) with hidden prompt injection to misclassify the fraudulent site as the legitimate DeBank platform. Testing across 26 LLMs showed 4 models vulnerable to the payment scam and 2 models susceptible to misclassification, demonstrating measurable real-world impact that varies by model and context.
#0014
Zscaler ThreatLabzabout 2 months ago5 min▣LLM reporthigh ThreatLabz identified a new attack campaign deploying 'Edgecution,' a malicious Microsoft Edge browser extension used by an initial access broker affiliated with Payouts King ransomware. The malware abuses the Chrome native messaging protocol to bridge a headless browser extension with a Python-based backdoor, enabling arbitrary code execution and filesystem access while evading traditional browser sandboxes.
#0015
Zscaler ThreatLabzabout 2 months ago5 min▣LLM reporthigh ThreatLabz identified a supply chain attack where the threat actor SmartApeSG compromised the widely used Okendo Reviews widget to inject malicious JavaScript. The loader employs environment checks, XOR deobfuscation, and staged execution to deliver ClickFix-style social engineering lures, ultimately aiming to deploy RATs and information stealers on desktop endpoints.
#0016
Zscaler ThreatLabzabout 2 months ago5 min▣LLM reporthigh The ThreatLabz 2026 Phishing and Initial Access Report highlights a shift towards highly targeted, AI-enabled phishing campaigns against the public sector. Despite a 20% overall drop in phishing volume, attackers are increasingly utilizing AI site builders, encrypted delivery channels, and AiTM/BiTM techniques to bypass traditional MFA and secure initial access.
#0017
Zscaler ThreatLabzabout 2 months ago6 min▣LLM reporthigh ThreatLabz identified a ClickFix campaign utilizing AI-generated typosquatting domains to impersonate Brazilian banks and deliver a PowerShell-based banking RAT dubbed SmartRAT. The malware establishes persistence via scheduled tasks or Windows services, communicates over a custom TCP protocol on port 51888, and features advanced capabilities including keylogging, fake banking overlays, and QR code interception for financial fraud.
#0018
Zscaler ThreatLabzabout 2 months ago6 min▣LLM reportcritical The Shai-Hulud software supply chain campaign has significantly evolved, expanding from npm to PyPI and shifting from maintainer compromise to CI/CD abuse. Recent waves demonstrate advanced techniques including OIDC token scraping to bypass SLSA provenance, IDE configuration file weaponization, and prompt injection designed to evade LLM-based security scanners.
#0019
Zscaler ThreatLabzabout 2 months ago4 min▣LLM reporthigh The Zscaler ThreatLabz 2026 Phishing and Initial Access Report highlights a shift from high-volume phishing to highly targeted campaigns leveraging AI site builders and encrypted channels. Attackers are increasingly utilizing AiTM and BiTM techniques to bypass MFA, while conducting massive reconnaissance via cloud infrastructure to identify exposed entry points.
#0020
Zscaler ThreatLabz2 months ago6 min▣LLM reporthigh ThreatLabz has identified MLTBackdoor, a highly obfuscated post-exploitation framework delivered via ClickFix social engineering lures. The malware utilizes Mixed Boolean-Arithmetic (MBA), Control Flow Flattening (CFF), and indirect system calls to evade detection, while maintaining persistence and control through a custom encrypted protocol, a Domain Generation Algorithm (DGA), and a Beacon Object File (BOF) loader.